CVE 8.6 HIGH

SuiteCRM: Authenticated SQL Injection Possible in Reschedule Call Module_CVE-2025-64488

8.6 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

Description

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 7.14.7 and below and 8.0.0-beta.1 through 8.9.0 8.0.0-beta.1, an attacker can craft a malicious call_id that alters the logic of the SQL query or injects arbitrary SQL. An attack can lead to unauthorized data access and data ex-filtration, complete database compromise, and other various issues. This issue is fixed in versions 7.14.8 and 8.9.1.

AI Analysis

Authenticated SQL injection vulnerability in the Reschedule Call Module, allowing attackers to alter SQL query logic or inject arbitrary SQL, potentially leading to unauthorized data access, data ex-filtration, and database compromise.

Basic Information

ID CVE-2025-64488
Source GitHub_M
Published Nov 7, 2025 at 23:59

Affected Product

Vendor SuiteCRM
Product SuiteCRM
Version >= 8.0.0-beta.1, < 8.9.1
Affected Versions SuiteCRM SuiteCRM >= 8.0.0-beta.1, < 8.9.1
SuiteCRM SuiteCRM < 7.14.8

CWE Classification

AI Assessment

AI Score 8.6 / 10
AI Severity High
Vendor SalesAgility
Product SuiteCRM
Version 7.14.7 and below, 8.0.0-beta.1 through 8.9.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.